生效日期:2026 年 7 月 1 日 · 版本 1.4.0

喵护照隐私政策

最近更新:2026 年 8 月 3 日

本隐私政策说明 Meowport(亦称“喵护照”,“本 App”,“我们”)在你使用 iOS、iPadOS、macOS、tvOS、小组件、App Intents、快捷指令、本地文档、导出数据包,以及面向中国大陆的 meowport.cn 和面向中国大陆以外地区的 meowport.app 相关网站时如何处理信息。

喵护照采用本地优先设计。在 1.0 版本中,我们不运营接收你猫咪记录的一般开发者服务器,也不运营自有的 AI 推理服务。除非你选择使用 Apple iCloud / CloudKit、共同照护分享、导出数据包、Apple 私有云计算、自定义 AI API、Mac 互联 / MCP 或支持渠道,大部分数据会留在你的设备上。

权威语言

本隐私政策仅提供简体中文和英文版本。中文和英文版本分别作为对应语言环境下的权威文本。喵护照不提供其他语言的机器翻译法律文本。其他语言的 App 标签、按钮、摘要、商店本地化文本或客服说明,仅用于产品导航或便利理解,不会修改、翻译或替代本隐私政策。

1. 重要摘要

2. 谁控制数据

仅存储在你设备上的数据,由你通过设备和本 App 控制。

iCloud / CloudKit 数据由 Apple 提供基础设施,并由你的 Apple ID 按 Apple 条款、iCloud 设置、CKShare 分享和地区服务安排控制访问。

通过 Apple 私有云计算处理的请求,由 Apple 作为其平台的一部分按 Apple 条款提供处理。喵护照不运营该基础设施,也不会取得该请求的副本。

自定义 AI API 数据由你配置的提供商按其条款和隐私政策处理。

你通过支持邮件或直接消息发送给我们的信息,由我们用于回应和处理请求。

3. 喵护照可能存储或处理的信息

取决于你使用的功能,喵护照可能存储或处理:

除非确有必要且合法,请不要录入人类医疗信息、政府身份证件号码、金融账户号码、密码或其他敏感信息。

4. 数据存储位置

本机

喵护照将 App 状态存储在 App 本地容器中,并可能在 App Group 容器中存储小组件快照或动作队列。当你启用或使用相关功能时,Spotlight、日历、提醒事项、通知、文件、照片和快捷指令等本地 Apple 系统服务也可能存储相关项目。

当 Apple 账户变化要求喵护照替换与账户绑定的迁移检查点时,一个范围严格限定、仅位于本机的账户迁移恢复隔离区可能保留已退役检查点,避免崩溃把替换过程静默变成不可逆删除。喵护照使用 Apple CryptoKit 的 AES-GCM 密封该检查点,以 HMAC-SHA256 指纹保护账户和迁移绑定,将安装级本地密钥及隔离账本置于 Apple 文件保护下,并把隔离目录排除在设备备份之外。该恢复辅助数据不是通用猫咪记录数据库,不能替代用户备份,也不会上传到 CloudKit 或喵护照服务器。

iCloud / CloudKit

如果启用,喵护照可能将当前同步快照、逐条记录的智能同步数据、备份包、CKShare 共同照护数据和相关元数据存储到你的 iCloud / CloudKit 账户。Apple 及适用地区的 iCloud 合作伙伴运营该基础设施。喵护照不声明这些记录受到额外 App 自有加密层保护。

家庭共同照护使用 Apple 的私有 CKShare。创建者建立家庭前,会在可见的逐猫清单中审阅拟提交的现有自有猫咪;这些猫咪可以默认勾选,但创建者可在明确确认前取消。受邀编辑者的猫咪保持私有,只有在其主动逐猫选择“提交至共同照护”后才进入家庭;查看者不能提交。接受邀请本身不会提交成员的私有猫咪。打开、取消或关闭 Apple 分享界面不会构成提交;只有用户明确确认且私有分享成功建立后,猫咪才会提交。只有已提交猫咪的记录和附件会因共同照护进入 iCloud 分享;未提交猫咪不会仅因用户创建、加入或编辑某个家庭而自动上传。

一个共同照护家庭可能由家庭管理分享和多位猫咪所有者分别控制的逐猫私有分享共同组成。加入时,受邀人可能先接受家庭管理分享,再分批接受一个或多个已提交猫咪的私有分享。受 Apple 服务、账户、网络、设备、存储和各猫咪所有者设备状态影响,这些步骤可能部分成功、延迟或需要重试;一个逐猫分享失败不会撤销已经成功接受的其他分享。喵护照应显示等待、失败或部分同步状态,不把尚未完成的家庭表述为完整同步。

为完成私有分享,喵护照可能处理 Apple 提供的不透明账户、记录、zone 和分享标识,以及仅供指定收件人接受分享所需的邀请元数据和邀请 URL。这些邀请不会设置为公开分享,邀请 URL 本身不会单独授予访问权限,也不会因被持有就成为“持有即授权”的凭证;实际访问仍取决于 Apple 账户、受邀参与者身份、接受状态和有效权限。原始邀请 URL 和 CloudKit token 不得写入 App 生成的诊断信息,也不会作为公开目录或公开链接发布。

接收到共享猫咪的设备会在成员保有访问权期间保留该猫咪记录的本地副本,与角色无关。在此之上,授予或接受编辑权限时,受支持的编辑者设备还会自动下载并保留附件的离线副本,以支持离线共同照护和记录写作。这会占用编辑者设备存储空间,并在由其他参与者控制的设备和 Apple 账户上形成猫咪数据副本。缓存可能因空间、网络、账户、权限、Apple 服务或附件可用性而不完整;App 应显示缓存状态而不把不完整副本称为完整。我们会在可用范围内使用 Apple 平台文件保护,并在系统支持且副本可重建时避免不必要的重复备份,但不声明额外 App 自有加密层。

如果前编辑者对其他参与者拥有的猫咪有未发送修改,App 会要求其选择保留本地、可另行导出的原家庭副本,或仅删除 App 控制的外来家庭副本和未发送的共同照护草稿。该选择绝不会删除成员自己拥有的猫咪,包括已经移回仅自己管理的已提交猫咪。删除自有猫咪须另行提出,并经过知情确认。

受支持客户端会执行更严格的 owner/editor/viewer 业务角色。查看者仅对有权访问的家庭猫咪保持只读;其自有猫咪和无关功能仍按普通免费版或 Pro 规则使用,查看者身份不会使整个 App 进入只读。已提交猫咪始终归提交者所有;提交者可以将其移回仅自己管理,家庭创建者不能据为己有、转移所有权或单方面撤回他人提交的猫咪。发起移回操作的受支持客户端在记录该选择后,会及时从本机家庭范围中隐藏并停止该猫咪的相关访问,同时保留提交者本地猫咪;其他受支持客户端在取得这一变更状态后跟进,Apple 层面的跨账户撤回可能稍后完成。移回仍在处理期间,受支持客户端会同时暂停该猫咪的共同照护和个人智能同步自动传输,避免通过两个路径重复发送。只有安全交接得到确认且用户有 Pro 时,个人智能同步才可恢复;没有 Pro 时,该猫咪仅保留在本机,或由用户手动进行 iCloud 备份或导出。Apple CKShare 的平台权限和喵护照业务角色并不完全相同;没有经验证的创建者撤权审计时,喵护照只会中性说明“CloudKit 确认此账户不再具有共同照护访问权限”,不会推断具体操作者或原因。

iCloud 智能同步是可选功能(属于喵护照 Pro),在登录同一 iCloud 账户的你自己的设备之间同步单条记录、宠物档案和家庭设置,并将这些记录存储在你的 iCloud 私有数据库中。加入共同照护家庭需要喵护照 Pro。成员接受家庭后,继续参与所必需的同步不以其持续持有 Pro 为条件,其范围仅包括有权访问的外来家庭猫咪和该成员已明确提交的自有猫咪。没有 Pro 时,其他未提交私有猫咪只在本机使用,或通过手动 iCloud 备份或导出迁移。记录内容字段通过 Apple 的 CloudKit 加密字段机制保存,该机制由 Apple 按其条款运营和管理密钥;如果你的 Apple 账户启用了高级数据保护,则按 Apple 文档适用 Apple 扩展的端到端保护。智能同步使用 CloudKit 静默变更通知来得知数据有更新;这些通知只表示有变化,不会把你的记录内容传送给我们。关闭智能同步会停止私有记录同步,但不会删除你的本地数据或已有的 iCloud 数据,也不会停止你继续参与已接受家庭所必需的授权共同照护同步。

导出包和分享文档

个人手动 iCloud 备份和普通个人导出只包括用户自己拥有的猫咪;所有仍在共同照护中的外来家庭猫咪(无论可编辑或只读),以及撤权后保留的原家庭副本,均不会进入这些个人数据包。另行授权的编辑者或前编辑者家庭副本导出可以包含本地已有的外来家庭内容,但会保留外来来源、列明不可用或未下载附件,并可能是部分导出。它不会使这些内容变成自有内容、获得个人智能同步资格或可提交至家庭。

当你导出 .meowportpkg、PDF、应急卡、家庭副本包或分享文本后,导出的文件或文本由接收或保存它的人控制。在导出或形成之后,喵护照无法控制受控导出流程之外的导出文件、截图或副本。旧版 .mewportpkg 数据包可能仍会为兼容性保留恢复能力。

Apple 端侧模型与 Apple 私有云计算

AI 管家有三条处理路径,具体适用哪一条,取决于你所选的模型和一项由你控制的设置。

选择 Apple 模型时,喵护照使用 Apple 端侧模型,该次请求在你的设备上处理。

Apple 私有云计算(Private Cloud Compute)是一项独立的可选能力。除非你在 AI 管家设置中自行开启,该能力始终保持关闭;选择 Apple 模型不会开启它,喵护照也不会代你开启。在其可用时,我们可能建议你开启,因为它有助于在隐私与模型能力之间取得更好的平衡,但是否开启由你决定。你的选择会被保存:该设置保持开启期间,在 Apple 授权资格、设备、地区、系统、账户、网络、额度以及喵护照当前适配条件允许的范围内,后续 Apple 模型对话会直接尝试通过私有云计算处理,不会再就每一条消息请求你确认。这是喵护照执行你此前选择并保存的处理偏好,而不是端侧模型判断自身能力不足后自行将请求升级至云端。

某次请求通过私有云计算处理时,对话内容、与该请求相关的宠物档案信息,以及回答该请求所需的其他上下文,会通过 Apple 私有云计算处理,而不再仅限于你的设备。喵护照无法事先告知某一次请求会在设备上完成还是通过私有云计算完成;该设置开启期间,也请不要认为全部数据都始终留在设备上。

私有云计算能否使用,取决于 Apple 授权与开发者资格、设备型号与操作系统版本、Apple 智能及相关系统设置、地区、语言、账户与网络状况、Apple 服务状态与额度及使用限制、Apple 政策/开发者计划/技术接口的调整,以及你已安装的喵护照版本是否仍满足适用的适配要求。上述条件均可能发生变化。

如果私有云计算暂时不可用,或某次请求未能通过私有云计算完成,喵护照可能改由 Apple 端侧路径完成该次请求。此类失败不会自动关闭你已保存的偏好,喵护照也不会因此将请求转交第三方模型提供商。如果你关闭该设置,Apple 模型将恢复为端侧处理。

私有云计算由 Apple 作为 Apple 平台的一部分运营。它不是喵护照的服务器,也不是下文所述的自定义 API;喵护照不运营自有的 AI 推理服务。Apple 在该环节如何处理数据,适用 Apple 自身的条款和隐私说明;我们仅在 Apple 现行官方文档可支持的范围内加以描述。

无论由哪条路径作答,喵护照自身的本地权限校验、共同照护角色和记录规则仍然适用。只读共同照护参与者不能借助 AI 写入记录;AI 回复本身不会完成任何更改,只有经你确认后才会新增或修改记录。

自定义 AI 提供商

自定义 AI 提供商与上述两条路径相互独立:只有在你配置并选择该提供商后,内容才会发送给第三方。如果你配置自定义 AI 提供商,相关内容会发送到你提供的端点。你的提供商可能按其政策存储、使用、训练、保留、审查、转移或删除数据。使用前请阅读该提供商条款。

Mac 互联 / MCP

Mac 互联是可选且由 Mac 承载的功能。iOS 可能在 Mac 互联页面打开时通过 Bonjour 发现本地 Mac 服务,并可能读取同一 iCloud 状态或未来心跳数据。Mac 端授权、工具范围、日志和 agent 行为由 Mac App 和你的 Mac 环境控制。

公共参考来源

当喵护照显示化验参考区间、疫苗节奏或其他公开参考信息时,App 可能内置或存储来源标识、来源 URL、发布日期/更新日期和最后复核日期。这些公共来源元数据用于展示出处和免责声明,独立于你的私有猫咪记录。

5. 我们如何使用信息

喵护照使用信息以:

在隐私法律要求合法依据的地方,依据可能包括提供你请求的服务、你的同意、履行法律义务、保护安全和防止滥用等合法利益,或处理索赔与支持请求。

6. 分享和披露

喵护照可能按以下方式披露或提供数据:

我们不会为了跨情境行为广告而出售或分享个人信息。

7. 购买和订阅

App Store 购买由 Apple 处理。喵护照可能接收用于解锁功能的交易状态、产品标识、权益状态和订阅信息,但付款详情、账单地址、退款、税费、家庭共享资格和取消由 Apple 处理。

8. 保留

喵护照会保留本地记录,直到你按设备和系统行为编辑、归档、导出、删除、替换、还原、清除或卸载。iCloud 当前快照可能为了保持新鲜而被覆盖。iCloud 智能同步在你的 iCloud 中的记录会随你的修改被新增、更新或移除;删除标记可能保留一段时间,以便你的其他设备得知删除。共同照护编辑者的受支持设备会在编辑权限有效期间自动保留共享记录和附件的离线副本;撤权后的保留、导出或删除按 App 提供的流程处理,但外部副本不受 App 控制。iCloud 备份版本设计为只保留有限数量的可选版本。AI 会话历史和附件可能在 App 中受限,以减少存储和上下文大小。

如果你在 App 内提交账户删除请求,清理开始前可能存在宽限期;若 Apple 服务不可用,部分云端清理步骤可能重试。本地删除不会移除已导出、分享、截图、由共同照护参与者保留、存储在 Apple 非喵护照 App 级控制范围内备份中的副本,也不会移除由自定义 AI 提供商处理的数据。

对于提供 90 天恢复入口的删除,喵护照会尽合理努力保留并核验受控本地副本和 CloudKit 副本,并显示准确的恢复截止日期以及“受保护、降级或不可用”状态。恢复入口不是保证或独立备份:设备丢失、账户丢失、用户删除 CloudKit zone、加密密钥重置、存储损坏、Apple 服务不可用,或所有受控副本同时不可读取,都可能导致 90 天内提前无法恢复。删除前我们会建议你导出独立备份,并要求你在知悉这些限制后自行确认是否继续。90 天恢复截止日是受控可恢复内容的清理到期点,不代表 Apple 或 CloudKit 服务器已在该时刻精确完成删除。如果届时没有获授权的受支持喵护照客户端获得执行机会,或 Apple 账户、网络或 CloudKit 不可用,受控 CloudKit 内容和受控备份的清理会在下一次可执行机会继续重试。完成前,产品会显示“待处理或部分完成”,不得表示 CloudKit 清理已经完成。清理完成后,为防止受支持客户端复活旧数据,可能继续保留不含猫咪内容的删除屏障元数据。外部副本、已导出文件、参与者副本、超出 App 级控制的 Apple/系统备份及任意旧版或被修改客户端仍在此保证范围之外。

支持邮件和法律请求可能保留至回应、遵守法律、解决争议和维护安全记录所需的期限。

8A. 在线应急卡公开投影

在线应急卡是与离线二维码和共同照护分离的自愿公开投影。所有者选择开启并确认字段后,App 会在设备上压缩所选头像、构建最小化投影,并使用认证加密写入 Apple CloudKit 公用数据库。公开记录包含密文、随机 nonce、格式/代数信息及有限运行字段;完整二维码或链接的 URL 片段携带解密密钥,片段通常不会随标准 HTTP 请求发送给 meowport.app。Apple 的 CloudKit 响应仍可能附带创建者标识、时间戳或其他系统元数据,网站托管方也可能处理请求 IP、时间、User-Agent 和错误日志。

持有完整二维码或链接的人可以读取并继续分享卡片。通过消息服务发送链接可能也会把完整链接提供给该服务。公开投影可能包括猫咪姓名、去除来源元数据并压缩的头像、品种、脱敏 ID 后四位、血型、过敏/禁忌、未标记康复的重要病史、当前关键用药,以及你有权提供的兽医或紧急联系人;不会主动征求人类健康资料、主人住址、完整猫咪 ID 或保险信息。自由文本按输入内容显示,可能不完整、过时或未经兽医核实。

页面显示最近一次成功发布的内容和受保护的发布时间。启用后,既有字段集内的数据、头像和 App 主题变化可能继续自动发布。首次开启、字段扩展和更换链接要求当前设备确认;法律或披露版本变化不自动撤下既有投影或阻断其既有字段自动更新,但 App 会在下次管理或预览时要求重新确认。

撤销或更换链接会尝试删除旧公开记录;在 Apple 服务、账号、网络或设备暂不可用时,可能显示撤销处理中并继续重试。Meowport 无法收回其他人已经保存、截图、打印、缓存、导出或转发的副本。共同照护成员关系的变化不会自动修改在线应急卡,反之亦然。

数据导出可包含在线卡状态、所选字段 ID、披露版本、同意记录摘要、最近成功发布时间和待清理代数,但不包含完整链接、记录名、密钥或 nonce;导入不会自动恢复公开发布。删除猫咪或账号时,App 会先记录可重试清理意图,再尝试删除受控公开记录和私密控制记录;在 CloudKit 确认删除或确认记录不存在前,界面应描述为待处理或部分完成。

9. 你的选择和控制

你可以:

iCloud、CloudKit、App Store 购买、设备备份、家庭共享和 Apple 账户数据等设置由 Apple 控制。

10. 你的隐私权

取决于你所在地,你可能拥有访问、更正、删除、导出、限制、反对或撤回同意等个人信息权利。由于大部分喵护照数据是本地数据或存储在你自己的 iCloud 账户中,许多权利可以直接在 App 或 Apple 设置中行使。

对于你通过支持或法律联系方式直接发送给我们的数据,中国大陆地区请联系 [email protected]。我们可能需要验证你的请求。我们不会因你行使隐私权而歧视你。

中国大陆地区用户:在适用情况下,你可以请求访问、复制、更正、删除、解释、撤回同意或注销账户。iCloud 服务基础设施和地区合作伙伴可能受 Apple 及地区 iCloud 条款约束。

其他地区用户:你所在地的强制性隐私、消费者保护或数据保护法律可能适用。请通过 [email protected] 联系我们。

11. 安全

我们在可用范围内使用 Apple 平台安全能力,例如 App 沙盒、用于自定义 API 密钥的钥匙串、已实现的文件保护、用于上述有限账户迁移恢复隔离区的 Apple CryptoKit、iCloud / CloudKit 访问控制、StoreKit 和通过 Apple 登录。隔离区的安装级本地文件密钥与存放在钥匙串中的自定义提供商 API 密钥相互独立。我们不保证绝对安全。

在适用法律允许范围内,若因本地副本、CloudKit zone、账户访问、设备、存储、Apple 服务或加密密钥不可用而无法恢复,我们不能保证或承担法律强制要求之外的恢复责任。本政策不排除或限制依法不得排除、不得限制的消费者、隐私、数据保护或其他法定权利。

你需要负责设备密码、Apple ID 安全、iCloud 分享、Mac 安全、API 提供商安全、导出数据包以及你选择分享的对象。

12. 儿童

喵护照不面向 13 岁以下儿童,也不应由儿童在没有适当父母或监护人同意的情况下提交个人信息。如果你认为儿童通过支持渠道直接向我们提供了个人信息,中国大陆地区请联系 [email protected]

13. 国际与地区处理

Apple、iCloud、Apple 私有云计算、自定义 AI 提供商、支持工具和网站托管方可能根据你的账户、位置、提供商和服务设置在不同地区处理数据。如果你选择境外提供商,你的数据可能按该提供商条款转移至相应地区。

14. 语言、争议地和政策变更

本隐私政策仅提供简体中文和英文版本。我们不提供其他语言的机器翻译法律文本,因为未经审阅的法律翻译可能改变法律含义并造成不必要风险。若法院、监管机构、应用商店或平台要求其他语言文本,该文本应另行准备或审阅,并仅在强制性法律要求范围内适用。

喵护照当前开发和运营人员位于中国上海。在法律允许的最大范围内,与本隐私政策相关的争议应先通过下方联系方式提交给我们;若无法友好解决,应由中国上海有管辖权的法院处理,或在双方另行同意或存在可执行仲裁约定时,以中国上海为仲裁地处理,除非法律另有规定。

当 App、法律、平台要求或数据流发生变化时,我们可能更新本隐私政策。如有重大变更,我们会尽合理努力通过 App 内、网站或发行说明通知。除非法律要求其他流程,变更后继续使用即表示更新后的政策适用。

15. 联系方式

若您在中国大陆以外的地区使用喵护照,请访问全球网站 https://meowport.app,并通过 [email protected][email protected] 查询适用于您所在地区的信息、获取支持或提交法律与隐私请求。

Effective date: July 1, 2026 · Version 1.4.0

Meowport Privacy Policy

Last updated: August 3, 2026

This Privacy Policy explains how Meowport, also known as 喵护照 ("Meowport", "the App", "we", "us", or "our"), handles information when you use Meowport on iOS, iPadOS, macOS, tvOS, widgets, App Intents, Shortcuts, local documents, export packages, and related websites under meowport.app.

Meowport is designed to be local-first. In version 1.0, we do not operate a general developer server that receives your cat records, and we do not operate an AI inference service of our own. Most data stays on your device unless you choose to use Apple iCloud / CloudKit, co-care sharing, export packages, Apple Private Cloud Compute, custom AI APIs, Mac link / MCP, or support channels.

Authoritative languages

This Privacy Policy is provided only in Simplified Chinese and English. Both Chinese and English versions are intended to be authoritative for their respective language contexts. Meowport does not provide machine-translated legal text in other languages. Any other-language app label, button, summary, store-localization text, or support explanation is for product navigation or convenience only and does not amend, translate, or replace this Privacy Policy.

1. Important summary

2. Who controls the data

For data stored only on your device, you control it through your device and the App.

For iCloud / CloudKit data, Apple provides the infrastructure and your Apple ID controls access according to Apple terms, iCloud settings, CKShare sharing, and regional service arrangements.

For requests processed through Apple Private Cloud Compute, Apple provides that processing as part of the Apple platform under Apple's terms. Meowport does not operate that infrastructure and does not receive a copy of the request.

For custom AI APIs, the provider you configure processes the data you send to that provider under its own terms and privacy policy.

For support emails or direct messages you send to us, we process the information you choose to provide so we can respond and manage the request.

3. Information Meowport may store or process

Depending on what you use, Meowport may store or process:

Do not enter human medical information, government ID numbers, financial account numbers, passwords, or other sensitive information unless truly necessary and lawful.

4. Where data is stored

On device

Meowport stores app state in the app's local container and may store widget snapshots or action queues in an App Group container. Local Apple system services such as Spotlight, Calendar, Reminders, Notifications, Files, Photos, and Shortcuts may store related items when you enable or use those features.

When an Apple-account change requires Meowport to replace an account-bound migration checkpoint, a narrow device-local account-migration recovery quarantine may preserve the retired checkpoint so that a crash does not silently turn the replacement into irreversible deletion. Meowport seals that checkpoint with Apple CryptoKit AES-GCM, uses HMAC-SHA256 fingerprints for account and transition bindings, stores the installation-local key and quarantine ledger with Apple file protection, and excludes the quarantine directory from device backup. This recovery sidecar is not the general cat-record database, is not a substitute for a user backup, and is not uploaded to CloudKit or a Meowport server.

iCloud / CloudKit

If enabled, Meowport may store current sync snapshots, per-record Smart Sync data, backup packages, CKShare co-care data, and related metadata in your iCloud / CloudKit account. Apple and applicable regional iCloud partners operate that infrastructure. Meowport does not claim that these records are protected by an additional app-owned encryption layer.

Family co-care uses Apple's private CKShare. Before creating a family, the creator reviews a visible per-cat list of existing owned cats proposed for submission. Those cats may be selected by default, but the creator can deselect them before giving explicit confirmation. An invited editor's cats stay private unless the editor actively chooses “Submit to co-care” for each cat; a viewer cannot submit. Accepting an invitation alone never submits a member's private cats. Opening, dismissing, or cancelling Apple's sharing screen does not submit a cat; submission occurs only after explicit confirmation and successful establishment of private sharing. Only records and attachments for submitted cats enter iCloud sharing for co-care, and creating, joining, or editing a family does not by itself upload an unsubmitted cat.

A co-care family may consist of a family-management share together with separate private per-cat shares controlled by each cat's owner. A member may first accept the family-management share and then accept one or more submitted-cat shares in batches. Apple-service, account, network, device, storage, and cat-owner-device conditions can make those steps partial, delayed, or retryable; one failed cat share does not roll back shares already accepted. Meowport should show pending, failed, or partially synchronized status and must not present an incomplete family as fully synchronized.

To complete private sharing, Meowport may process opaque Apple-provided account, record, zone, and share identifiers, together with invitation metadata and invitation URLs needed by designated recipients. These invitations are not configured as public shares, and possession of an invitation URL does not itself grant access; access still depends on the Apple account, invited-participant identity, acceptance state, and effective permissions. Raw invitation URLs and CloudKit tokens must not be included in App-generated diagnostic output or published as a public directory or public link.

A device that receives a shared cat retains a local copy of that cat's records for as long as the member keeps access, whatever the role. On top of that, when editor access is granted or accepted, supported editor devices automatically download and retain offline copies of attachments for offline collaboration and record writing. This uses storage on editor devices and creates cat-data copies on devices and Apple accounts controlled by other participants. Caching may be incomplete because of storage, network, account, permission, Apple-service, or attachment availability; the App should report cache state and must not describe an incomplete copy as complete. We use Apple platform file protection where available and avoid unnecessary redundant backup where supported and the cache is recreatable, but we do not claim an additional app-owned encryption layer.

If a former editor has unsent changes for cats owned by other participants, the App asks that former editor to choose between retaining a local, separately exportable former-family copy and deleting only the locally controlled foreign-family copies and unsent co-care drafts. This choice never deletes a cat owned by that member, including a submitted cat already returned to private management. Deleting an owned cat is a separate, informed request.

Supported clients enforce stricter owner/editor/viewer product roles. A viewer is read-only only for authorized family cats; the viewer's own cats and unrelated functions continue under ordinary Free or Pro rules, and viewer status does not make the entire App read-only. A submitted cat remains owned by its submitter. The submitter can return it to private management, while another family creator cannot claim it, transfer it, or independently withdraw it. The supported client where you initiate the return records your choice and promptly hides and stops that cat's family access while preserving the submitter's local cat. Other supported clients follow after they receive that change, while Apple-level withdrawal across accounts may complete later. While return to private management is pending, supported clients pause both co-care and personal Smart Sync automatic transmission for that cat to avoid sending it through two paths. Personal Smart Sync may resume after the handoff is confirmed and only with Pro; without Pro, the cat remains local or moves through manual iCloud backup or export. Apple CKShare platform permissions and Meowport product roles are not identical. Without a validated creator-authored revocation audit, Meowport states neutrally that CloudKit confirms this account no longer has co-care access and does not infer the person or reason responsible.

iCloud Smart Sync is an optional feature (part of Meowport Pro) that syncs individual records, pet profiles, and household settings between your own devices signed in to the same iCloud account. Joining a co-care family requires Meowport Pro. Once a member has accepted a family, the synchronization needed to keep participating does not depend on that member keeping Pro, and its scope is limited to authorized foreign family cats and the member's expressly submitted owned cats. Without Pro, other unsubmitted private cats stay on-device or move through manual iCloud backup or export. Record content fields are saved through Apple's encrypted CloudKit field mechanism, which Apple operates and keys under Apple's terms; if your Apple account uses Advanced Data Protection, Apple's expanded end-to-end protection applies according to Apple's documentation. Smart Sync uses silent CloudKit change notifications to learn that something changed; those notifications signal freshness and do not deliver your record content to us. Turning Smart Sync off stops private record syncing without deleting local or existing iCloud data, and it does not stop authorized co-care synchronization required to continue participating in an accepted family.

Export packages and shared documents

Personal manual iCloud backup and general personal export include only cats you own. All active foreign family cats, whether editable or read-only, and retained former-family copies are excluded from those structured personal packages. A separately authorized editor or former-editor family-copy export may include locally available foreign-family content, keeps its foreign origin, identifies unavailable or not-downloaded attachments, and may be partial. It does not make that content owned, eligible for personal Smart Sync, or eligible for family submission.

When you export a .meowportpkg, PDF, emergency card, family-copy package, or share text, the exported file or text is controlled by whoever receives or stores it. Meowport cannot control exports, screenshots, or copies made outside Meowport's controlled export flow after they are shared or created. Legacy .mewportpkg packages may remain restorable for compatibility.

Apple on-device model and Apple Private Cloud Compute

AI Butler has three processing paths, and which one applies depends on the model you select and one setting you control.

When you select the Apple model, Meowport uses Apple's on-device model and that request is processed on your device.

Apple Private Cloud Compute is a separate, optional capability. It is off unless you turn it on yourself in AI Butler settings; selecting the Apple model does not enable it, and Meowport does not enable it for you. Where it is available we may recommend it, because it can offer a better balance between privacy and model capability, but the decision is yours. Your choice is saved. While the setting remains on, later Apple-model conversations attempt Private Cloud Compute directly when Apple eligibility, your device, region, system, account, network, quota, and Meowport's current integration permit it, and you are not asked to confirm again for each message. That is Meowport carrying out a processing preference you chose earlier; it is not the on-device model deciding that it is incapable and escalating your request to the cloud on its own.

When a request is handled through Private Cloud Compute, the conversation content, the pet-profile facts relevant to that request, and other context needed to answer it are processed through Apple Private Cloud Compute rather than only on your device. Meowport cannot tell you in advance whether a particular request will run on your device or through Private Cloud Compute, and while the setting is on you should not assume that all data stays on the device.

Whether Private Cloud Compute can be used at all depends on Apple entitlements and developer eligibility, your device and operating-system version, Apple Intelligence and related system settings, region, language, account, and network conditions, Apple service status, quotas and usage restrictions, changes to Apple's policies, developer programs, or technical interfaces, and whether the Meowport version you have installed still meets the applicable integration requirements. Any of these can change.

If Private Cloud Compute is temporarily unavailable or a request through it does not succeed, Meowport may complete that request on Apple's on-device path instead. A failure of that kind does not switch your saved preference off, and Meowport does not move the request to a third-party model provider. If you turn the setting off, the Apple model returns to on-device processing.

Private Cloud Compute is operated by Apple as part of the Apple platform. It is not a Meowport server, and it is not the custom API described below; Meowport does not run an AI inference service of its own. Apple's own terms and privacy documentation govern how Apple handles that processing, and we describe it only to the extent Apple's current documentation supports.

Whichever path answers a request, Meowport's own local permission checks, co-care roles, and record rules still apply. A read-only co-care participant cannot use AI to write records, and an AI reply never completes a change on its own: a record is created or modified only after you confirm it.

Custom AI providers

A custom AI provider is a separate path from both of the above. Content is sent to a third party only after you configure and select that provider. If you configure a custom AI provider, relevant content is sent to the endpoint you provide. Your provider may store, use, train on, retain, review, transfer, or delete data according to its own policies. Review that provider's terms before using it.

Mac link / MCP

Mac link is opt-in and Mac-hosted. iOS may discover a local Mac service using Bonjour while the Mac link screen is open and may read same-iCloud status or future heartbeat data. Mac-side grants, tool scopes, logs, and agent behavior are controlled by the Mac app and your Mac environment.

Public reference sources

When Meowport displays lab reference interval context, vaccine schedule context, or other public reference information, the App may bundle or store source identifiers, source URLs, publication/update dates, and last reviewed dates. This public reference source metadata is used to show provenance and disclaimers; it is separate from your private cat records.

5. How we use information

Meowport uses information to:

Where privacy law requires a legal basis, the basis may include providing the service you requested, your consent, compliance with legal obligations, protecting legitimate interests such as security and abuse prevention, or handling claims and support requests.

6. Sharing and disclosure

Meowport may disclose or make data available as follows:

We do not sell or share personal information for cross-context behavioral advertising.

7. Purchases and subscriptions

App Store purchases are handled by Apple. Meowport may receive transaction status, product identifiers, entitlement state, and subscription information needed to unlock features, but Apple handles payment details, billing address, refunds, taxes, family sharing eligibility, and cancellation.

8. Retention

Meowport keeps local records until you edit, archive, export, delete, replace, restore, clear, or uninstall according to device and system behavior. iCloud current snapshots may be overwritten for freshness. iCloud Smart Sync records in your iCloud are added, updated, or removed as you change records; deletion markers may be kept for a period so your other devices can learn about deletions. Participant devices retain local copies of shared records while access remains active, and supported co-care editor devices additionally retain offline copies of attachments while editor access remains active; retention, export, or deletion after revocation follows the App flow, but external copies remain outside App control. iCloud backup versions are designed to keep a limited number of selectable versions. AI conversation history and attachments may be limited in the App to reduce storage and context size.

If you submit an account deletion request in the App, there may be a grace period before cleanup begins, and some cloud cleanup steps may retry if Apple services are unavailable. Local deletion does not remove copies already exported, shared, screenshotted, retained by co-care participants, stored in Apple backups outside Meowport's app-level control, or processed by custom AI providers.

For deletions with a 90-day recovery entry, Meowport uses reasonable efforts to retain and verify controlled local and CloudKit copies and shows the exact recovery deadline and a protected, degraded, or unavailable state. The recovery entry is not a guarantee or an independent backup. Device loss, account loss, a user-deleted CloudKit zone, reset encryption keys, storage corruption, unavailable Apple services, or simultaneous loss of all controlled copies may make recovery impossible before the 90 days end. Before deletion, we advise you to export an independent backup and ask you to decide whether to proceed after learning these limits. The 90-day recovery deadline is the cleanup-due point for controlled recoverable content; it does not mean that Apple or CloudKit servers completed deletion at that exact time. If no authorized supported Meowport client has an execution opportunity at the deadline, or the Apple account, network, or CloudKit is unavailable, cleanup of controlled CloudKit content and controlled backups will retry at the next available execution opportunity. Until cleanup finishes, Meowport reports it as pending or partially complete and does not state that CloudKit cleanup has completed. After completion, minimal deletion-barrier metadata that contains no cat content may remain to keep supported clients from resurrecting old data. External copies, exports, participant copies, Apple or system backups outside App-level control, and arbitrary obsolete or modified clients remain outside this guarantee.

Support emails and legal requests may be retained as long as needed to respond, comply with law, resolve disputes, and maintain security records.

8A. Online Emergency Card public projection

The Online Emergency Card is an optional public projection separate from the offline QR and Co-Care. After the owner enables it and confirms the field set, the App compresses any selected profile photo on device, builds a minimized projection, and writes it with authenticated encryption to the Apple CloudKit public database. The public record contains ciphertext, a random nonce, format and generation information, and limited operational fields. The URL fragment in the complete QR or link carries the decryption key and is normally not sent to meowport.app in a standard HTTP request. Apple's CloudKit response may still attach a creator identifier, timestamps, or other system metadata, and the website host may process request IP address, time, User-Agent, and error logs.

Anyone who holds the complete QR or link can read and further share the card. Sending the link through a messaging service may also provide the complete link to that service. The projection may include the cat's name, a metadata-stripped compressed profile photo, breed, masked last four pet-ID characters, blood type, allergies or cautions, critical history not marked recovered, current critical medications, and veterinarian or emergency contacts you are authorized to provide. It does not solicit human health data, the owner's home address, the complete pet ID, or insurance information. Free text is displayed as entered and may be incomplete, outdated, or not veterinarian-verified.

The page displays the last successfully published content and its protected publication time. Once enabled, changed values, photo, and App theme within the existing field set may continue automatic publication. First enablement, field expansion, and link replacement require confirmation on the current publishing device. A legal or disclosure version change does not automatically remove the existing projection or block automatic updates within its existing field set, but the App will require the user to reconfirm at the next management or preview interaction.

Revocation or link replacement attempts to delete the former public record. If Apple services, the account, network, or device are temporarily unavailable, the UI may show revocation pending and continue retrying. Meowport cannot recall copies another person has saved, screenshotted, printed, cached, exported, or forwarded. Co-Care membership changes do not automatically change the Online Emergency Card, and vice versa.

A data export may include card state, selected field IDs, disclosure version, consent receipt summary, last successful publication time, and pending-cleanup generation count, but it excludes the complete link, record name, key, and nonce; importing the export does not automatically restore publication. When a cat or account is deleted, the App records a retryable cleanup intent before attempting to delete controlled public records and the private control record. Until CloudKit confirms deletion or confirmed absence, the UI should describe the result as pending or partial.

9. Your choices and controls

You can:

Some settings, such as iCloud, CloudKit, App Store purchases, device backups, family sharing, and Apple account data, are controlled by Apple.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or withdraw consent for personal information. Because most Meowport data is local or in your own iCloud account, many rights can be exercised directly in the App or through Apple settings.

For data you sent directly to us through support or legal contact, email [email protected]. We may need to verify your request. We will not discriminate against you for exercising privacy rights.

California users: we do not sell or share personal information as those terms are used for cross-context behavioral advertising, and we do not knowingly collect personal information from children under 13.

EEA/UK users: where applicable, you may contact us about access, rectification, erasure, restriction, portability, objection, withdrawal of consent, or complaints. You may also contact your local data protection authority.

China-region users: where applicable, you may request access, copy, correction, deletion, explanation, withdrawal of consent, or account cancellation. iCloud service infrastructure and regional partners may be governed by Apple and regional iCloud terms.

11. Security

We use Apple platform security where available, such as app sandboxing, Keychain for custom API keys, file protection where implemented, Apple CryptoKit for the narrow account-migration recovery quarantine described above, iCloud / CloudKit access controls, StoreKit, and Sign in with Apple. The quarantine's installation-local file key is separate from custom-provider API keys stored in Keychain. We do not guarantee perfect security.

To the extent permitted by applicable law, we cannot guarantee recovery or accept responsibility beyond liability the law requires when local copies, a CloudKit zone, account access, a device, storage, Apple services, or encryption keys are unavailable. This Policy does not exclude or limit consumer, privacy, data-protection, or other statutory rights that cannot lawfully be excluded or limited.

You are responsible for device passcodes, Apple ID security, iCloud sharing, Mac security, API provider security, exported packages, and who you share data with.

12. Children

Meowport is not directed to children under 13 and should not be used by children to submit personal information without appropriate parent or guardian consent. If you believe a child provided personal information to us directly through support channels, contact [email protected].

13. International and regional processing

Apple, iCloud, Apple Private Cloud Compute, custom AI providers, support tools, and website hosts may process data in different regions depending on your account, location, provider, and service settings. If you choose a provider outside your region, your data may be transferred there according to that provider's terms.

14. Language, venue, and changes to this policy

This Privacy Policy is provided only in Simplified Chinese and English. We do not provide machine-translated legal text in other languages because unreviewed legal translations can change legal meaning and create avoidable risk. If a court, regulator, app store, or platform requires another language, that text must be prepared or reviewed separately and will apply only to the extent mandatory law requires.

Meowport's current development and operation personnel are located in Shanghai, China. To the maximum extent permitted by law, disputes related to this Privacy Policy should first be raised with us at the contact address below and, if not resolved informally, should be handled in Shanghai, China through the competent court or, where mutually agreed or otherwise enforceable, arbitration seated in Shanghai, unless mandatory law requires otherwise.

We may update this Privacy Policy when the App, laws, platform requirements, or data flows change. If changes are material, we will use reasonable in-app, website, or release-note notice. Continued use after changes means the updated policy applies, except where law requires otherwise.

15. Contact

用户服务条款 · meowport.cn/legal · meowport.cn
若您在中国大陆以外的地区使用喵护照,请访问全球网站 meowport.app 查询适用于您所在地区的信息和支持。